Exploited in the wild GlobalProtect Qilin auth-bypass Palo Alto Networks ransomware
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
CVE Tools coverage
The Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks' GlobalProtect VPN software (CVE-2026-0257) to gain unauthorized access and deploy ransomware. The flaw was patched on May 13, but attackers began using it as early as May 17, with CISA adding it to its Known Exploited Vulnerabilities list on May 29. Cybersecurity firm Arctic Wolf confirmed multiple breaches linked to this exploit, resulting in widespread encryption of victim systems. With over 170,000 exposed GlobalProtect instances tracked online, urgent remediation is advised for any unpatched deployments.